First published: Tue Sep 16 2008(Updated: )
Finder in Apple Mac OS X 10.5 through 10.5.4 does not properly update permission data in the Get Info window after a lock operation that modifies Sharing & Permissions in a filesystem, which might allow local users to leverage weak permissions that were not intended by an administrator.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | =10.5.2 | |
macOS Yosemite | =10.5.1 | |
Apple Mac OS X Server | =10.5.1 | |
macOS Yosemite | =10.5.3 | |
Apple Mac OS X Server | =10.5.3 | |
macOS Yosemite | =10.5 | |
Apple Mac OS X Server | =10.5.4 | |
macOS Yosemite | =10.5.2 | |
Apple Mac OS X Server | =10.5 | |
macOS Yosemite | =10.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2331 is considered a medium severity vulnerability due to potential unauthorized access to sensitive files.
To fix CVE-2008-2331, Apple recommends upgrading to a later version of Mac OS X that addresses this permission issue.
CVE-2008-2331 affects Mac OS X versions 10.5 through 10.5.4, including both client and server versions.
CVE-2008-2331 is a local privilege escalation vulnerability related to improper permission handling in the Finder.
No, CVE-2008-2331 is a local vulnerability that requires physical access to the affected machine.